1. Introduction & Scope
Hexful.com is the data controller for personal data collected via hexful.com and the Hexful Chrome extension (together, the “Services”).
The Services are operated from the United Kingdom but accessible worldwide. Regardless of location, this English-language policy governs our processing. Where non‑waivable local laws (e.g. EU GDPR, California CPRA) grant additional rights, Hexful will honour them as required.
The Services are not directed to children under 13.
2. Data We Collect
2.1 Data You Provide
Category | Examples | Purpose |
User Content | Saved Palettes, Searches, Image Upload, Contrast Checks | Provide core functionality |
2.2 Data Collected Automatically
Device & usage logs (IP address, browser type, pages viewed, error logs) collected via Google Analytics 4 (IP anonymised, 14‑month retention).
2.3 Extension Data
Colour values processed locally; palette metadata is only transmitted when sync is enabled, over encrypted TLS 1.3.
3. How We Use Data & Legal Bases
- Contract: Operate, maintain, and deliver the Services.
- Legitimate Interests: Improve user experience, secure the Services, prevent fraud.
- Consent: Marketing emails, non‑essential cookies.
- Legal Obligation: Tax, accounting, and regulatory compliance.
Automated decision‑making: Palette‑suggestion algorithms are limited to aesthetic recommendations and do not produce significant legal effects.
4. Cookies
Essential cookies (session, security) are set under PECR Reg 6(4). Non‑essential cookies (currently GA4) are loaded after page load.
Advertising cookies: Hexful does not serve personalised ads today but reserves the right to introduce advertising in the future. We will seek fresh consent and update this policy before setting any new advertising cookies.
5. Your Rights
UK GDPR rights: access, rectification, erasure, restriction, objection, data portability, withdraw consent (response within 30 days).
EEA/Swiss users: your EU GDPR rights mirror the UK rights above. California residents: Hexful does not sell personal information; you may exercise CPRA rights (access, deletion, correction, opt‑out of sale/share) by emailing hexfulapp@gmail.com. We respond within 45 days where permitted.
6. Sharing & International Transfers
We share data only with UK/EEA processors (AWS UK, Stripe IE, Google Ireland). Transfers to the US rely on the UK–US Data Bridge certification or ICO‑approved IDTA Standard Contractual Clauses where certification is unavailable. A Data Processing Agreement is available on request.
7. Security, Breach Notification & ROPA
Security: TLS 1.3 in transit, AES‑256 at rest, multi‑factor authentication for staff, annual penetration testing.
Record‑of‑Processing: We maintain a ROPA under Article 30 UK GDPR, available to the ICO on request.
Breach Notification: We will notify the ICO and affected users without undue delay and, where feasible, within 72 hours of becoming aware of a personal‑data breach.
1. Overview & Acceptance
The Services (website and Chrome extension) are available worldwide; however, this contract is governed exclusively by English law, and any dispute must be brought before the courts of England & Wales, except where non‑waivable consumer‑protection laws in your jurisdiction require otherwise.
The Services are free of charge and provided “as is” / “as available” at your own risk. Nothing in these Terms affects statutory consumer rights.
2. Intellectual Property & Licence
2.1 Proprietary Rights: All software, source code, object code, algorithms, models, and the user interface (the “Software”) are Hexful’s confidential property. The Services incorporate the open‑source Color Thief (© 2011–2020 Lokesh Dhakar, MIT License); full text at GitHub (no warranty).
2.2 Licence: You receive a personal, non‑exclusive, revocable, non‑transferable licence to access the web Service via a standard browser and install the Chrome extension solely to generate and manage colour palettes.
2.3 Restrictions: You must not:
(i) copy, reproduce, or create derivative works;
(ii) reverse‑engineer, decompile, disassemble, or attempt to discover source code or trade secrets;
(iii) remove or alter proprietary notices;
(iv) use the Service output to train or benchmark competing models;
(v) access the Service to build a competitive offering;
(vi) export or re-export the Software to sanctioned destinations.
2.4 Confidentiality: You will keep the Software confidential with at least reasonable care.
2.5 Injunctive Relief: You acknowledge that breach may cause irreparable harm, entitling Hexful to equitable relief without bond.
2.6 No Assignment & No Third‑Party Rights: Licences may not be assigned, and only you and Hexful have enforcement rights (Contracts (Rights of Third Parties) Act 1999 excluded).
3. Acceptable Use & Compliance
- No unauthorized scraping, crawling, or data‑mining.
- No reverse‑engineering, decompiling, or disassembly.
- No removal of watermarks or notices.
- No use of output to train competing AI models.
- No export to embargoed or sanctioned regions or parties.
- No uploading of infringing or unlawful content.
4. Free Service, Future Ads & Paid Plans
Services are currently free and ad‑free. Hexful reserves the right to introduce paid tiers and/or third‑party ads with at least 30 days’ prior banner or email notice. Continued use constitutes acceptance.
5. Availability, Modification & Force Majeure
Target uptime 99.9% (no SLA). Hexful may modify, suspend, or discontinue any feature or the extension at any time without liability. Beta features carry no warranty and may be withdrawn without notice. Hexful is not liable for delays or failures from Force Majeure (e.g., natural disasters, internet outages, other services downtime and external issues).
6. Termination & Survival
Hexful may suspend or terminate your access immediately for breach. On termination, delete all copies of the extension and cease use. Surviving sections: 2 (IP & Licence), 3 (Acceptable Use), 5 (Availability), 7 (Liability), 8 (Law & Misc).
7. Disclaimers & Liability
1. No Value Provided. The Tool and this site are offered free of charge and provide no intrinsic or assignable monetary value to You.
2. Warranty Disclaimer. To the extent permitted by law, Hexful disclaims all warranties, express or implied, including but not limited to any warranties of merchantability, fitness for a particular purpose, non‑infringement, accuracy, or availability.
3. Zero Liability. Hexful’s total aggregate liability to You is zero. Under no circumstances shall Hexful be liable for any indirect, consequential, special, punitive, or exemplary damages, including loss of profit, data, or goodwill, arising out of or related to Your use of or inability to use the Tool.
4. Local Law Exception. Some jurisdictions do not allow the exclusion of certain warranties or the limitation of liability for consequential or incidental damages. In such jurisdictions, the above exclusions and limitations apply only to the maximum extent permitted by local law.
8. Governing Law & Miscellaneous
English law governs these Terms; exclusive jurisdiction of England & Wales courts, except where non‑waivable laws require otherwise. Entire agreement; severability; English language controls.